The Future of Audit Oversight

In creating the Public Company Accounting Oversight Board (PCAOB or Board), Congress fundamentally changed the system of oversight for the auditing profession.[1] The profession’s authority to write its own auditing, quality control, ethics, and independence standards and to discipline itself was removed, replaced by an independent regulator required to act in the interests of investors and the public. [2]   

The PCAOB’s implementation of the investor protection mission, however, is not complete. More needs to be done to integrate this mission into the standard-setting, inspection, and enforcement processes. Moreover, this need is taking place during a rapidly changing and challenging environment – the unprecedented economic disruption in the global economy from the pandemic, the inability of the audit process to uncover what appear to be readily apparent financial frauds, the increased reliance by investors on information outside of the financial statements, and the material impact of climate change and other environmental, social and governance (ESG) matters on the financial statements.

In my concluding remarks as a Board member, I want to discuss some ways that the PCAOB can further fulfill the investor protection mission mandated by Congress. None of these comments should be viewed as criticisms of the staff. They are areas that deserve greater consideration by the Board. 

I. The Future of Auditing, Attestation, Quality Control, Ethics, and Independence Standards

Stakeholders agree on the need to improve audit quality and the importance of auditor communication with investors and the public but do not always agree on the method of accomplishing these goals.[3] In determining auditing, attestation, quality control, ethics, and independence standards, the PCAOB should more explicitly take into account and implement the views of investors. 

Investors generally favor standards that reflect a blend of principles and objective bright-line factors.[4] Objective factors establish a predictable and consistent floor with overlying principles providing flexibility for discretion and judgment.[5]

Investors and the public also generally favor the use of governance features designed to ensure the integrity of the decision-making process.[6] Audit firms are for profit enterprises; audit quality comes at a cost. Confidence in the decision-making process requires that these potentially conflicting goals be acknowledged and structural safeguards be put in place to keep them separate.[7]

The PCAOB auditing standards do not entirely reflect these expectations. Mostly written during the era of self-regulation, investors views were largely absent from the process. In addition, they are out of date.[8] They do not adequately address a business environment dominated by technology and digitalization, the changes arising out of the evolving nature of the audit, and lessons learned from the current health pandemic.

This should change. The PCAOB’s mission requires not only greater interaction with investors when considering revisions to the auditing, attestation, quality control, ethics, and independence standards but also a shift in approach that reflects these views.[9] 

In addition to changes to the standards, the PCAOB should advance the investor protection mission through an increased use of guidance to interpret existing standards.

When Congress gave the PCAOB the authority to write and adopt standards, this included the interpretation of those very standards. The existing suite of standards is filled with vague and undefined terms, often interfering with adequate inspection and enforcement. For example:

  • The PCAOB’s standard regarding an auditor’s consideration of possible illegal acts does not require auditors to communicate to audit committees any such acts uncovered during the audit that are “clearly inconsequential”[10] Guidance could provide greater insight into when an act, while not material, is nonetheless considered consequential under the standard.[11]
  • In considering the risk of fraud in a financial statement audit, audits must include unpredictable procedures.[12] Academic evidence suggests that in fact these so-called unpredictable procedures have become predictable.[13] Guidance could be used to ensure that this does not occur.
  • The standard for considering materiality for purposes of determining the “nature, timing, and extent of audit procedures” requires only that the level be “appropriate in light of the particular circumstances.”[14] Levels that are set too high can result in an inadequate audit. Yet guidance has not been issued that seeks to ensure that materiality is set at appropriate levels.[15]  

The current approach, a holdover from the era of self-regulation, is to allow these terms largely to be interpreted by each firm in their methodology. This results in an “expectations gap,” with a chasm separating what investors and other users expect and what firms believe they are required to do. This “gap” can be narrowed through thoughtful and useful guidance issued by the PCAOB that ensures these terms are construed in a manner thatconsistent with the intent of the standardmeets the expectation of investors and the inspection and enforcement needs of the PCAOB. 

II. PCAOB Inspections

Inspections are mostly designed and performed to assess compliance with applicable standards and requirements.[16] This can, however, be an insufficient measure of audit quality, particularly given the out of date nature of many of the standards. Indeed, the approach raises the concern that audit quality will be equated with a firm’s deficiency rate.  

The interests of investors and the public would be better implemented through an approach to inspections that included as an objective an explicit focus on the quality of financial reporting.[17] Such an objective would entail greater emphasis on audits of issuers with potential departures from GAAP, on the areas of the financial statements deemed important to investors on a qualitative basis, and on the procedures used by audit firms to assess the risk of fraud and the reporting of illegal acts.

A focus on financial disclosure would also allow the inspections process to provide investors and the public with insight into the application of accounting standards by issuers and broker-dealers. The accuracy of estimates and valuations in the financial statements can depend upon the assumptions used by management. Firms may examine these assumptions as part of the audit. The inspections process can generate reports on whether and how particular assumptions such as climate change are used in connection with particular estimates and valuations.

III. PCAOB Enforcement

The enforcement function of the PCAOB is an important one. The Division of Enforcement and Investigations (DEI) often investigates and recommends actions arising from inspection findings, including those involving overseas firms.

Enforcement, however, can be used more directly to benefit investors, shareholders, and the public by helping to ensure the integrity of mandatory disclosure by audit firms required by the PCAOB and used in making investment and voting decisions.

The PCAOB has in place two sets of disclosure requirements applicable to audit firms.  

First, implemented by the prior Board, the PCAOB has adopted standards and rules that require firms to reveal the identity of the engagement partner, the other auditors used in an audit,[18] and the length of time the firm has served as the auditor.[19] In addition, audit reports may need to include critical audit matters, those areas of the audit that kept the auditor up at night.[20] The value and importance of this information to investors and the public is clear and will only increase over time. [21]  

Second, the PCAOB has established a central data base that provides the public with basic information about firms that audit public companies and SEC-registered broker-dealers. These reports identify, among other things, the firm’s clients[22] and certain disciplinary proceedings, including those brought by other domestic and foreign regulators.[23] The data base is an important source of information for investors, including customers of broker-dealers, and the public. Had such a data base been in place for broker-dealers before 2010, additional red flags relating to the fraud conducted by Bernie Madoff would have been available.[24]   

The PCAOB infrequently brings actions for violations of these requirements.[25] Moreover, when this occurs, the sanctions do not appear to be sufficient to create the necessary incentives to adequately deter violations.[26] This can be seen in particular with respect to Chinese audit firms. As of January 12, 2021, approximately 37 audit firms from China were registered with the PCAOB.[27] Of those firms, 14 had not filed an annual report for 2020, including four registered for over a decade that never filed the reports.[28]

The Board can encourage an approach to enforcement that gives greater priority to ensuring the completeness, accuracy, and timeliness of these disclosures, whether in the audit report or in filings with the PCAOB and ensuring that firms required to be registered are in fact registered.

Another important step designed to benefit investors and the public in a mission consistent fashion would be the revision of guidelines implemented in 2019 that reduced the instances when enforcement settlements identified the issuer where a deficient audit allegedly occurred.[29] The Board should provide that, at a minimum, any such guidelines explicitly take into account the need for, and benefits of, the information to investors and shareholders.[30]

IV. Audit Relevancy

There is an ongoing global debate over audit relevance and whether audit currently meets the expectations and needs of investors and other capital market participants.

The information environment of companies and investors has changed radically since glossy annual reports were mailed to public company shareholders. The annual audit needs to evolve to address the information environment. Failure to do so will cause the audit to continue to lose value in the eyes of investors and other market participants.

Evolution of the audit needs to address investor expectations with respect to assurance. This includes such topics as the role of the auditor in providing assurance for information outside the financial statements, whether non-GAAP or ESG metrics; the role of firms in evaluating threats to a company’s ability to continue as a going-concern; the role of firms in the detection of fraud (a topic elevated by the collapse of Wirecard in Europe); the identification and communication of potential illegal acts, such as bribes; and the tension between maintaining a high quality audit and succumbing to the commercial interests of an audit firm.

The investor protection mission would be advanced by having the PCAOB serve as a catalyst in this area.[31] The PCAOB is uniquely positioned to understand the interests of investors, the capacity of audit firms, and the impact on the financial disclosure process. This would also allow the PCAOB to lead rather than follow in the global debate on these issues.[32]  

V. The PCAOB Board

The mission to act in the interests of investors and the public requires a Board that actively engages with these stakeholders on a regular and structured basis.

Currently, the full Board rarely meets with investors and their representatives. And while there was, in 2020, a single “roundtable” held with a select group of asset managers,[33] the meeting was neither with the entire Board nor webcast or otherwise made public.[34] Much like interactions with large audit firms, the full Board should meet regularly with, and hear directly from, investors and investor representatives, relying on predetermined agendas that ensure feedback on topics relevant to the decision making process.[35]

The Board should also further the interests of investors and the public through a heightened commitment to transparency and public accountability. As Justice Brandeis famously said, sunlight is the best disinfectant.[36] Strong public accountability helps ensure robust commitment to the investor protection mission.[37] This requires a level of transparency sufficient to permit investors and the public to adequately monitor the activities and decisions of the PCAOB.[38]

